Skip to content

build(deps): bump actions/cache from 4 to 6 - #2

Merged
tonythethompson merged 2 commits into
mainfrom
dependabot/github_actions/actions/cache-6
Jul 29, 2026
Merged

build(deps): bump actions/cache from 4 to 6#2
tonythethompson merged 2 commits into
mainfrom
dependabot/github_actions/actions/cache-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 25, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/cache from 4 to 6.

Release notes

Sourced from actions/cache's releases.

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v.5.0.2

v5.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/cache's changelog.

Releases

How to prepare a release

[!NOTE] Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

6.1.0

6.0.0

  • Updated @actions/cache to ^6.0.1, @actions/core to ^3.0.1, @actions/exec to ^3.0.0, @actions/io to ^3.0.2
  • Migrated to ESM module system
  • Upgraded Jest to v30 and test infrastructure to be ESM compatible

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

... (truncated)

Commits
  • 55cc834 Merge pull request #1768 from jasongin/readonly-cache
  • d8cd72f Bump @​actions/cache to v6.1.0 - handle cache write error due to RO token
  • 2c8a9bd Merge pull request #1760 from actions/samirat/esm_migration_and_package_update
  • e9b91fd Prettier fixes
  • e4884b8 Rebuild dist
  • 10baf01 Fixed licenses
  • e39b386 Fix test mock return order
  • b692820 PR feedback
  • 6074912 Rebuild dist bundles as ESM to match type:module
  • 5a912e8 Fix lint and jest issues
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 25, 2026
@graphite-app

graphite-app Bot commented Jul 25, 2026

Copy link
Copy Markdown

How to use the Graphite Merge Queue

Add either label to this PR to merge it via the merge queue:

  • queue - adds this PR to the back of the merge queue
  • fast - for urgent changes, fast-track this PR to the front of the merge queue

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

tonythethompson pushed a commit that referenced this pull request Jul 27, 2026
Gated (private desktop repo) needs multi-key trust-ring lookup and
revocation for license verification, but under the Phase 2 submodule
model it consumes Trackdub.Licensing read-only and can no longer fork
LicenseTokenValidator/LicenseService in place to get it, per
docs/plans/trackdub-gated-split-manifest.md (Trackdub-gated PR #2) §1.

Adds ILicenseSignatureTrustStore: resolves a PEM public key per token
key id, or null to reject an unknown/revoked key. LicenseService takes
it as a new optional constructor parameter; omitting it preserves the
existing single embedded-key behavior exactly. LicenseTokenClaims gains
an optional KeyId parsed from the token's "kid" claim and threaded into
LicenseTokenValidator.VerifySignature, which now resolves the key
per-store when one is supplied instead of always using the embedded
key. Revocation falls out of the same seam: a trust store returning
null for a given key id fails verification closed, so no separate
revocation plumbing is needed.

Everything added is internal to Trackdub.Licensing except the new
public interface and the optional constructor parameter, so the
project keeps its zero-ProjectReference, BCL-only-crypto invariants
(LicensingIsolationTests) and the dependency graph in AGENTS.md is
unchanged.

Production-policy concerns from the same manifest section -- rejecting
dev-unlimited tokens under a production trust ring, and startup
validation of production ring configuration -- are deliberately left
out of this seam. Both read from already-public LicenseValidationResult
fields (UnlimitedActivations, degradation reason) and are naturally
implementable as a decorator over ILicenseInitializer/ILicenseTierProvider
in the consuming product, without needing any further core change.

The manifest's other blocker, headless export-tier enforcement, needs
no core change at all: Trackdub.Sdk's TrackdubBuilder.ConfigureServices
(-> TrackdubOptions/HeadlessTrackdubOptions.ServiceConfigurator ->
HeadlessCompositionRoot.AddHeadlessTrackdub step 7) already lets a
consumer register a custom IExportTierGate for Cli/Sdk hosts. Trackdub.Cli
goes through this same builder. That seam already exists; using it is
Phase 2.3 work in the desktop repo, not something this PR needs to add.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014Yd883rGkFx5xN1TyT1Lzf

@tonythethompson tonythethompson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Push an empty commit to this PR so that CI tests restart

@tonythethompson tonythethompson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dependabot rebase.

Bumps [actions/cache](https://github.com/actions/cache) from 4 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/cache-6 branch from 0823b12 to a1c883c Compare July 27, 2026 05:57
@github-actions

Copy link
Copy Markdown

This is a major version update. Auto-merge is disabled for major bumps. Please review manually.

@kilo-code-bot

kilo-code-bot Bot commented Jul 27, 2026

Copy link
Copy Markdown

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (1 file)
  • .github/workflows/code-coverage.yml

Reviewed by step-3.7-flash · Input: 80.7K · Output: 3K · Cached: 143.6K

@github-actions

Copy link
Copy Markdown

This is a major version update. Auto-merge is disabled for major bumps. Please review manually.

@tonythethompson
tonythethompson merged commit 70fc75a into main Jul 29, 2026
12 checks passed
@tonythethompson
tonythethompson deleted the dependabot/github_actions/actions/cache-6 branch July 29, 2026 01:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant